GDPR

Data subject access requests, right to erasure with financial exemptions, retention schedules, data tombstones, and Article 30 processing records.

Request received

Aug 1

Data compiled

Aug 3

Export generated

Aug 5

Delivered to subject

Aug 30

25 days remaining · Art. 15

Data subject access requests, fulfilled in 30 days.

When a customer requests their data (Art. 15), Cronos compiles every record associated with their identity — orders, payments, bookings, messages, consent logs — into a structured JSON and human-readable PDF export. The request is tracked with a 30-day deadline and a status log visible to the data protection officer.

Before erasure

NameMarco Rossi
Emailmarco.rossi@email
AddressVia Roma 42, Milano
Phone+39 348 123 4567
Art. 17 erasure

After erasure

Name████████
Email████████
Address████████
Phone████████
InvoicesRetained (GoBD)

Right to erasure with financial exemptions.

When a customer invokes the right to erasure (Art. 17), Cronos removes all personal data — name, email, address, phone, profile picture. Financial records required by GoBD (invoices, tax-relevant bookings) are retained but anonymized. The customer is informed which data was deleted and which was retained under legal obligation.

Retention periods

InvoicesGoBD
10 years
Payment recordsGoBD
10 years
Customer dataafter last activity
2 years
Marketing consentuntil withdrawal
Auto-purge runs nightly

Retention schedule with automatic purge.

Every data category has a defined retention period. Customer personal data is purged 2 years after the last activity. Marketing consents are kept until withdrawal. Invoices and financial records are retained for 10 years per GoBD. Cronos runs a scheduled purge job that removes expired records automatically — no manual cleanup needed.

Order #4821Aug 6, 2026

████████

█████████████

Tombstoned
Bouquet — Summer Mix€34.00
VAT 19%€6.46
Total€40.46

Order intact · customer PII removed · reports accurate

Data tombstones preserve referential integrity.

When a customer record is deleted, a tombstone replaces it — a placeholder that retains the ID and non-personal metadata so that historical orders, invoices, and bookings still link correctly. No PII remains in the tombstone. This means reports and audits remain accurate without retaining personal data.

Art. 30 — Record of Processing
Category
Purpose
Basis
Customer profiles
Order fulfillment
Contract
Payment data
Processing
Contract
Email addresses
Marketing
Consent
Usage analytics
Improvement
Consent
12 categories · 3 transfers (SCCs)Export PDF →

Article 30 processing records, auto-generated.

GDPR Article 30 requires maintaining a record of processing activities. Cronos generates this automatically — data categories, purposes, legal bases, recipients, retention periods, and third-country transfers are all documented. The record is updated when processing changes and is exportable for supervisory authority audits.

Consent preferences

Marketing emails

Granted Mar 12

Analytics tracking

Granted Mar 12

Third-party sharing

Withdrawn Jul 3

Withdraw anytime · changes logged with timestamp

Consent management with withdrawal tracking.

Every consent — marketing emails, analytics, third-party sharing — is recorded with a timestamp, purpose, and granular scope. Customers can withdraw consent at any time from their account settings. Withdrawals are logged and immediately halt the corresponding processing. No consent is assumed or bundled.

Frequently asked questions

How does Cronos handle data subject access requests?

When a customer requests their data under Article 15, Cronos compiles all records tied to their identity — orders, payments, bookings, messages, consent logs — into a JSON and PDF export. The request is tracked with a 30-day deadline per GDPR. The data protection officer can monitor status from the admin panel.

What happens when a customer requests erasure?

All personal data (name, email, address, phone, profile) is removed. Financial records required by GoBD (invoices, tax-relevant bookings) are retained but anonymized — the customer is informed which data was deleted and which was kept under legal obligation. A data tombstone preserves referential integrity so historical reports remain accurate.

What is a data tombstone?

A tombstone is a placeholder record that replaces a deleted customer. It retains the record ID and non-personal metadata so that historical orders, invoices, and bookings still link correctly. No PII remains in the tombstone. This allows accurate reporting and auditing without retaining personal data.

How long is personal data retained?

Customer personal data is purged 2 years after the last activity. Marketing consents are kept until withdrawal. Invoices and financial records are retained for 10 years per GoBD. The retention schedule is configurable per data category and enforced by an automatic purge job.

Does Cronos maintain Article 30 processing records?

Yes. The record of processing activities is generated automatically — data categories, purposes, legal bases, recipients, retention periods, and third-country transfers are all documented. The record updates when processing changes and is exportable for supervisory authority audits at any time.

How is consent managed?

Every consent is recorded with a timestamp, purpose, and granular scope. Customers can withdraw consent from their account settings at any time. Withdrawals are logged and immediately halt the corresponding processing. No consent is assumed, bundled, or hidden in terms and conditions.

What about data transfers outside the EU?

Any third-country transfer is documented in the Article 30 records with the applicable safeguard (Standard Contractual Clauses, adequacy decision, or explicit consent). Cronos uses hosting in the EU (Railway PostgreSQL) and US-based processors (Stripe, OpenAI) under SCCs. The transfer records are available for audit.

Who is the data protection officer?

The data protection officer (DPO) is designated by the business operating Cronos. The DPO has access to the admin panel where DSARs, erasure requests, consent logs, and processing records are managed. If no DPO is designated, the business owner is responsible by default.

← All compliance